Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They would just get an email saying that icloudbackupsupport@gmail.com (his phony address) accessed the account immediately after giving their info to icloudbackupsupport@gmail.com. He could even have told them to expect and ignore such an email.


There should be a request for approving the login attempt, and if you say yes, you get a six digit code to enter on the device trying to connect. Then when that succeeds, you get another push notification about it succeeding.


And thats what happens on any iOS with 2FA enabled.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: